Salesforce MFA Enforcement Pause: What You Need to Know
Salesforce has temporarily paused the enforcement of mandatory multi-factor authentication (MFA) for all employee users due to issues with security key prompts during enrollment. The new MFA enforcement schedule now begins with Sandboxes on July 6, 2026, and Production environments starting July 20, 2026, with staggered rollouts. Admins should continue preparing for MFA compliance, as the delay does not cancel the requirement. This pause provides breathing room but reinforces that MFA, especially phishing-resistant methods, remain critical for securing Salesforce orgs.
- MFA enforcement for all employee users is temporarily paused but will resume on a new schedule.
- Sandbox MFA enforcement starts July 6, 2026, and Production on July 20, 2026.
- No org-level opt-out will be allowed once enforcement resumes; MFA toggle becomes permanent.
- Phishing-resistant MFA methods (security keys, built-in authenticators) are strongly recommended.
- Admins should continue MFA preparation as the delay does not cancel the mandate.
Salesforce paused multi-factor authentication (MFA) enforcement for all employee users recently. The move was confirmed through a notice dated July 1 on the MFA enforcement Help page that stated, “Salesforce has placed these changes on hold. Plans to resume will be announced soon.” The notice, updated on July 2, now states that the rollout for the MFA for All Employee Users enforcement is resuming per a new schedule. Here’s what you need to know. What’s Going On? If you’ve been active in the Salesforce ecosystem lately, then you’ve probably heard of the latest security requirements they’ve been pushing for this year . The roadmap includes email verification, MFA updates, and step-up authentication on report exports. These changes even caused chaos for solo admins getting locked out of their own orgs , and it’s been the talk of the town on Reddit as well. Well, on July 1, Salesforce hit pause on one of its biggest security mandates of the year.